Struct PqdsaKeyPair
pub struct PqdsaKeyPair { /* private fields */ }aws-lc and crypto and std only.Expand description
A PQDSA (Post-Quantum Digital Signature Algorithm) key pair, used for signing and verification.
Implementations§
§impl PqdsaKeyPair
impl PqdsaKeyPair
pub fn generate(
algorithm: &'static PqdsaSigningAlgorithm,
) -> Result<PqdsaKeyPair, Unspecified>
pub fn generate( algorithm: &'static PqdsaSigningAlgorithm, ) -> Result<PqdsaKeyPair, Unspecified>
Generates a new PQDSA key pair for the specified algorithm.
§Errors
Returns Unspecified if the key generation fails.
pub fn from_pkcs8(
algorithm: &'static PqdsaSigningAlgorithm,
pkcs8: &[u8],
) -> Result<PqdsaKeyPair, KeyRejected>
pub fn from_pkcs8( algorithm: &'static PqdsaSigningAlgorithm, pkcs8: &[u8], ) -> Result<PqdsaKeyPair, KeyRejected>
Constructs a key pair from the parsing of PKCS#8.
This accepts either the seed or expanded private key encodings. If both are present in the input, they are validated to agree with each other.
§Errors
Returns Unspecified if the key is not valid for the specified signing algorithm.
pub fn from_raw_private_key(
algorithm: &'static PqdsaSigningAlgorithm,
raw_private_key: &[u8],
) -> Result<PqdsaKeyPair, KeyRejected>
pub fn from_raw_private_key( algorithm: &'static PqdsaSigningAlgorithm, raw_private_key: &[u8], ) -> Result<PqdsaKeyPair, KeyRejected>
Constructs a key pair from raw private key bytes.
This expects the expanded form of the raw private key bytes.
§Errors
Returns Unspecified if the key is not valid for the specified signing algorithm.
pub fn from_seed(
algorithm: &'static PqdsaSigningAlgorithm,
seed: &[u8],
) -> Result<PqdsaKeyPair, KeyRejected>
pub fn from_seed( algorithm: &'static PqdsaSigningAlgorithm, seed: &[u8], ) -> Result<PqdsaKeyPair, KeyRejected>
Constructs a key pair deterministically from a 32-byte seed.
Per FIPS 204, the same seed always produces the same key pair. This enables reproducible key generation for testing, ACVP validation, and interoperability with implementations that store seeds rather than expanded private keys.
algorithm is the PqdsaSigningAlgorithm to be associated with the key pair.
seed is the 32-byte seed from which the key pair is deterministically derived.
All ML-DSA variants (ML-DSA-44, ML-DSA-65, ML-DSA-87) use 32-byte seeds.
§Security Considerations
The seed is the root secret. Compromise of the seed is equivalent to compromise of the private key. Callers are responsible for generating seeds from a cryptographically secure random source and protecting them accordingly.
The seed should be produced from random entropy such as through crate::rand::fill.
However, for users requiring FIPS, the seed must be produced from
Self::generate. The Self::to_pkcs8v1 method serializes the private key in seed form.
AWS-LC keeps the seed in the internal representation when possible, but if PqdsaKeyPair
is constructed from the expanded form (via Self::from_raw_private_key) the seed cannot
be obtained and Self::to_pkcs8v1 will fail.
This method expands the seed into the full private key internally. The expanded private key
can be retrieved via Self::private_key and serialized via
PqdsaPrivateKey::as_raw_bytes.
§Errors
Returns KeyRejected::too_small() if seed.len() < 32.
Returns KeyRejected::too_large() if seed.len() > 32.
Returns KeyRejected::unspecified() if the underlying cryptographic operation fails.
pub fn to_pkcs8v1(&self) -> Result<Document, Unspecified>
pub fn to_pkcs8v1(&self) -> Result<Document, Unspecified>
Serializes the private key to PKCS#8 v1 DER.
This currently serializes the seed. If the seed is not available (for example when this
PqdsaKeyPair was constructed from the expanded private key via
Self::from_raw_private_key), serialization fails and this currently returns an error. A
future implementation may encode the expanded form of the key instead.
§Errors
Returns Unspecified if serialization fails.
pub fn sign(
&self,
msg: &[u8],
signature: &mut [u8],
) -> Result<usize, Unspecified>
pub fn sign( &self, msg: &[u8], signature: &mut [u8], ) -> Result<usize, Unspecified>
Uses this key to sign the message provided. The signature is written to the signature
slice provided, which must be at least PqdsaSigningAlgorithm::signature_len bytes
long. It returns the length of the signature on success.
§Errors
Returns Unspecified if signature is too small or if signing fails.
pub fn algorithm(&self) -> &'static PqdsaSigningAlgorithm
pub fn algorithm(&self) -> &'static PqdsaSigningAlgorithm
Returns the signing algorithm associated with this key pair.
pub fn private_key(&self) -> PqdsaPrivateKey<'_>
pub fn private_key(&self) -> PqdsaPrivateKey<'_>
Returns the private key associated with this key pair.
Trait Implementations§
§impl Debug for PqdsaKeyPair
impl Debug for PqdsaKeyPair
§impl KeyPair for PqdsaKeyPair
impl KeyPair for PqdsaKeyPair
§fn public_key(&self) -> &<PqdsaKeyPair as KeyPair>::PublicKey
fn public_key(&self) -> &<PqdsaKeyPair as KeyPair>::PublicKey
impl Send for PqdsaKeyPair
impl Sync for PqdsaKeyPair
Auto Trait Implementations§
impl Freeze for PqdsaKeyPair
impl RefUnwindSafe for PqdsaKeyPair
impl Unpin for PqdsaKeyPair
impl UnsafeUnpin for PqdsaKeyPair
impl UnwindSafe for PqdsaKeyPair
Blanket Implementations§
§impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
§impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
§impl<T> Conv for T
impl<T> Conv for T
impl<T> ErasedDestructor for Twhere
T: 'static,
§impl<T> FutureExt for T
impl<T> FutureExt for T
§fn with_context(self, otel_cx: Context) -> WithContext<Self> ⓘ
fn with_context(self, otel_cx: Context) -> WithContext<Self> ⓘ
§fn with_current_context(self) -> WithContext<Self> ⓘ
fn with_current_context(self) -> WithContext<Self> ⓘ
§impl<T> Instrument for T
impl<T> Instrument for T
§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more§impl<T> IntoRequest<T> for T
impl<T> IntoRequest<T> for T
§fn into_request(self) -> Request<T>
fn into_request(self) -> Request<T>
T in a rama_grpc::Request§impl<T> Pipe for Twhere
T: ?Sized,
impl<T> Pipe for Twhere
T: ?Sized,
§fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> Rwhere
Self: Sized,
fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> Rwhere
Self: Sized,
§fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> Rwhere
R: 'a,
fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> Rwhere
R: 'a,
self and passes that borrow into the pipe function. Read more§fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> Rwhere
R: 'a,
fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> Rwhere
R: 'a,
self and passes that borrow into the pipe function. Read more§fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
§fn pipe_borrow_mut<'a, B, R>(
&'a mut self,
func: impl FnOnce(&'a mut B) -> R,
) -> R
fn pipe_borrow_mut<'a, B, R>( &'a mut self, func: impl FnOnce(&'a mut B) -> R, ) -> R
§fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
self, then passes self.as_ref() into the pipe function.§fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
self, then passes self.as_mut() into the pipe
function.§fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
self, then passes self.deref() into the pipe function.§impl<T> Pointable for T
impl<T> Pointable for T
§impl<T> PolicyExt for Twhere
T: ?Sized,
impl<T> PolicyExt for Twhere
T: ?Sized,
§fn and<P, B, E>(self, other: P) -> And<T, P>
fn and<P, B, E>(self, other: P) -> And<T, P>
Policy that returns Action::Follow only if self and other return
Action::Follow. Read more§impl<T, U> RamaTryFrom<T> for Uwhere
U: TryFrom<T>,
impl<T, U> RamaTryFrom<T> for Uwhere
U: TryFrom<T>,
type Error = <U as TryFrom<T>>::Error
fn rama_try_from(value: T) -> Result<U, <U as RamaTryFrom<T>>::Error>
§impl<T, U, CrateMarker> RamaTryInto<U, CrateMarker> for Twhere
U: RamaTryFrom<T, CrateMarker>,
impl<T, U, CrateMarker> RamaTryInto<U, CrateMarker> for Twhere
U: RamaTryFrom<T, CrateMarker>,
type Error = <U as RamaTryFrom<T, CrateMarker>>::Error
fn rama_try_into(self) -> Result<U, <U as RamaTryFrom<T, CrateMarker>>::Error>
impl<T> Read<Exclusive, BecauseExclusive> for Twhere
T: ?Sized,
§impl<T> Tap for T
impl<T> Tap for T
§fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
Borrow<B> of a value. Read more§fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
BorrowMut<B> of a value. Read more§fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
AsRef<R> view of a value. Read more§fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
AsMut<R> view of a value. Read more§fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
Deref::Target of a value. Read more§fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
Deref::Target of a value. Read more§fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self
fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self
.tap() only in debug builds, and is erased in release builds.§fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self
fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self
.tap_mut() only in debug builds, and is erased in release
builds.§fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
.tap_borrow() only in debug builds, and is erased in release
builds.§fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
.tap_borrow_mut() only in debug builds, and is erased in release
builds.§fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
.tap_ref() only in debug builds, and is erased in release
builds.§fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
.tap_ref_mut() only in debug builds, and is erased in release
builds.§fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
.tap_deref() only in debug builds, and is erased in release
builds.